← Builds
Public data

Build one account list per compliance norm

The client helps organisations get audit-ready against several security norms. We scraped 20+ public registers into one account list per norm: a public-sector baseline, a sector standard, an EU regulation and an information security certification. Web-search subagents filled in missing domains and headcounts, a fixed five-signal score ranked the regulation list, and the first contact batch was capped at four people per company. The same base was later reused for a second client's five ICPs.

Works ifYour buyers fall under a security norm or law, and public registers show who is in scope.

Built for · B2B services · Europe
TypeScriptNeonClaudePythonLinkedInGoogle Sheets
Get the prompt for your coding agent

The system

~/builds/compliance-norm-registers
01Source

Government register

Public bodies

Local and national government bodies.

TypeScript
843

Certification register

Certified organisations

The norm register with its version, plus sector member lists.

1,416

Regulator and sector lists

Critical sectors

Regulator lists per sector.

1,311

Member lists

Industry members

Trade association members.

556
Resolve and dedupregistration number is the key, not the domainNeon
02Enrich

Web-search subagents

Missing domains

18 agents, 100 companies each.

Claude
93% found

Web-search subagents

Headcount

Only for norms with a size threshold.

Claude
70% found
3,515 accounts · 100% with a domainenrichment at $0
03Segment

Certified

Old version only

Still has to move to the current norm.

708

Certified

Current version

138

Regulation list

Ranked /100

sectorsizesecurity contactnorm overlapmatch
Python
1,310
Contacts from the client's LinkedIn exportonly at companies already on the listLinkedIn
04Cut

Top 300

Max 4 contacts per company

192 security, 108 IT.

105 companies
One account list per norm, and a ranked first batch.

The signal

An organisation is listed in a register that puts it in scope for a security norm. For one certification, it still holds the old version.

Why it predicts a purchase

Being in scope means audits or legal duties exist before anyone reaches out. The register that proves it also tells you the sector tier, and for a certification, which version the organisation holds and whether a move to the current one is still ahead.

How it works

01

One source per norm

Each norm gets the registers that prove who is in scope: a government register of public bodies, a certification register plus sector member lists, regulator lists per sector, and trade association member lists. 20+ sources, 3,515 accounts in the delivered list, every one with a domain.

02

Keep the norm version

The certification register is one static page that shows the norm version on every certificate. Organisations with only old-version certificates became their own segment: 708 of 1,416. They still have to move to the current version, so the list carries its own timing.

03

Score with a fixed formula

The regulation list of 1,310 accounts was ranked on five signals already in the data: sector tier from the source register, size, a known security contact, overlap with other norms and match certainty. The score is plain code with no model in it, and every row carries its breakdown next to the total.

04

Cap contacts per company

Contacts came from the client's own LinkedIn export, kept only where the company was already on the list: 2,150 people at 299 companies, split into a security persona and an IT persona by title. The first top 300 landed on 33 companies. A cap of 4 per company spread it over 105: 192 security and 108 IT contacts.

Build notes

  • A domain is not a company key. Several public bodies share one domain, and one operator appeared ten times on a regulator list. The national registration number is the identity. 214 duplicate domains were merged and 302 facility rows dropped.
  • A search-engine scrape for the 1,733 missing domains hit a captcha. 18 web-search subagents with 100 companies each found 93% in about 30 minutes, at no data cost. Headcount was harder to find: 70% of 1,339.
  • Check the sector tiers against the law text before tuning weights. A research pass against the regulation put one sector a tier higher than assumed, which moved 251 rows into the top sector tier.
  • Match contacts to companies on LinkedIn URL, then domain, never on name alone. Name matching showed 53% of accounts with a contact. The real number was 23%.

Questions

Why split accounts by norm version?

The certification register shows which version of the norm each organisation holds. An organisation still on the old version has to move to the current one, which is a dated reason to reach out. Here that was 708 of 1,416 certified organisations.

Why cap contacts per company?

Without a cap, the top 300 contacts sat at 33 companies, with one company taking 11 or more slots. A cap of 4 per company spread the same cut over 105 companies.

More builds

All builds →
Public data

Detect 163 B2B tools from a company's website and DNS

Your product replaces, integrates with or sells to users of specific tools.

Open→
Public data

Reach companies before their public deadline

Your buyers make public promises with a deadline.

Open→
Public data

Reach companies hiring for what you sell

You sell a service that companies also try to hire for.

Open→

The next step

Let's get started.